cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 30 of 339
CVE-2025-36930P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36930 [HIGH] CWE-120 CVE-2025-36930: In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds c In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36927P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36927 [HIGH] CWE-120 CVE-2025-36927: In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a mi In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36932P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36932 [HIGH] CWE-20 CVE-2025-36932: In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32324P3HIGHCVSS 7.8v15.0v16.0+2 more2025-09-04
CVE-2025-32324 [HIGH] CWE-441 CVE-2025-32324: In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48583P3HIGHCVSS 7.8v14.0v15.0+4 more2025-12-08
CVE-2025-48583 [HIGH] CVE-2025-48583: In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0045P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0045 [HIGH] CWE-693 CVE-2026-0045: In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connec In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48652P3HIGHCVSS 7.8v15.0v16.0+6 more2026-06-01
CVE-2025-48652 [HIGH] CWE-693 CVE-2025-48652: In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48541P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48541 [HIGH] CWE-20 CVE-2025-48541: In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user pro In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0088P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0088 [HIGH] CWE-451 CVE-2026-0088: In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security di In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0078P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0078 [HIGH] CWE-20 CVE-2026-0078: In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36906P3HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2025-36906 [HIGH] CWE-122 CVE-2025-36906: In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32322P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-04
CVE-2025-32322 [HIGH] CWE-20 CVE-2025-32322: In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recording capabilities due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-56190P3HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2024-56190 [HIGH] CWE-20 CVE-2024-56190: In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48632P3HIGHCVSS 7.8v14.0v15.0+4 more2025-12-08
CVE-2025-48632 [HIGH] CWE-20 CVE-2025-48632: In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to p In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0096P3HIGHCVSS 7.8v16.0v16.0-qpr2_beta_1+4 more2026-06-01
CVE-2026-0096 [HIGH] CWE-451 CVE-2026-0096: In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgettin In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36925P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36925 [HIGH] CWE-787 CVE-2025-36925: In WAVES_send_data_to_dsp of libaoc_waves.c, there is a possible out of bounds write due to a missin In WAVES_send_data_to_dsp of libaoc_waves.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36919P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36919 [HIGH] CWE-415 CVE-2025-36919: In aocc_read of aoc_channel_dev.c, there is a possible double free due to improper locking. This cou In aocc_read of aoc_channel_dev.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36936P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36936 [HIGH] CWE-190 CVE-2025-36936: In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an i In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36931P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36931 [HIGH] CWE-120 CVE-2025-36931: In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds c In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26418P3HIGHCVSS 7.8v14.0v15.0+2 more2026-06-01
CVE-2025-26418 [HIGH] CWE-862 CVE-2025-26418: In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass t In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase